测试医疗大模型记忆患者数据的能力,发现隐私泄露风险。
An Investigation of Memorization Risk in Healthcare Foundation Models
- 用黑盒测试方法检测模型在嵌入和生成层面的记忆行为
- 验证了医疗大模型对特定人群存在隐私泄露风险
- 开源工具包支持可复现的医疗AI隐私评估
基于大规模去标识化电子健康记录(EHR)训练的基座模型在临床应用中前景广阔,但其记忆患者信息的能力引发严重隐私担忧。本文提出一套黑盒评估测试框架,用于评估结构化EHR数据训练的基座模型中的隐私相关记忆风险。该框架涵盖嵌入层与生成层的记忆探测方法,旨在区分模型泛化能力与有害记忆,在临床相关场景中识别潜在隐私威胁。研究特别关注脆弱子群体的隐私暴露风险。我们在一个公开的EHR基座模型上验证了该方法,并发布开源工具包,以促进医疗AI领域可复现、协作式的隐私评估。
原文摘要 · Abstract (English)
Foundation models trained on large-scale de-identified electronic health records (EHRs) hold promise for clinical applications. However, their capacity to memorize patient information raises important privacy concerns. In this work, we introduce a suite of black-box evaluation tests to assess privacy-related memorization risks in foundation models trained on structured EHR data. Our framework includes methods for probing memorization at both the embedding and generative levels, and aims to distinguish between model generalization and harmful memorization in clinically relevant settings. We contextualize memorization in terms of its potential to compromise patient privacy, particularly for vulnerable subgroups. We validate our approach on a publicly available EHR foundation model and release an open-source toolkit to facilitate reproducible and collaborative privacy assessments in healthcare AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。